Transport and Application Protocol Scrubbing

نویسندگان

  • G. Robert Malan
  • David Watson
  • Farnam Jahanian
  • Paul Howell
چکیده

This paper describes the design and implementation of a protocol scrubber, a transparent interposition mechanism for explicitly removing network attacks at both the transport and application protocol layers. The transport scrubber supports downstream passive network-based intrusion detection systems; whereas the application scrubbing mechanism supports transparent fail-closed active network-based intrusion detection systems. The transport scrubber’s role is to convert ambiguous network flows into well-behaved flows that are unequivocally interpreted by all downstream endpoints. As an example, this paper presents the implementation of a TCP/IP scrubber that eliminates insertion and evasion attacks – attacks that use ambiguities to subvert detection – on passive network-based intrusion detection systems, while preserving high performance. The application protocol scrubbing mechanism is used as a substrate for building fail-closed active network-based intrusion detections systems that can respond to attacks by eliding or modifying application data flows in real-time. This paper presents the high-performance implementation of a general purpose transparent application-level scrubbing toolkit in the FreeBSD kernel.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Hand-rubbing with an aqueous alcoholic solution vs traditional surgical hand-scrubbing and 30-day surgical site infection rates: a randomized equivalence study.

CONTEXT Surgical site infections prolong hospital stays, are among the leading nosocomial causes of morbidity, and a source of excess medical costs. Clinical studies comparing the risk of nosocomial infection after different hand antisepsis protocols are scarce. OBJECTIVE To compare the effectiveness of hand-cleansing protocols in preventing surgical site infections during routine surgical pr...

متن کامل

Fast Local Scrubbing for FPGA’s Configuration Memory

Memory scrubbing is used to mitigate Single Event Upsets (SEUs) on susceptible devices. In the case of Field Programmable Gate Arrays (FPGAs), configuration memory scrubbing is generally used in conjunction with Triple Modular Redundancy (TMR) to increase reliability in spaceborne applications. Current solutions require a subsystem able to read and write from the configuration memory and retrie...

متن کامل

Modeling, Simulation, and Optimization of a Front-end System for Acetylene Hydrogenation Reactors

The modeling, simulation, and dynamic optimization of an industrial reaction system for acetylene hydrogenation are discussed in the present work. The process consists of three adiabatic fixed-bed reactors, in series, with interstage cooling. These reactors are located after the compression and the caustic scrubbing sections of an ethylene plant, characterizing a front-end system; in contrast t...

متن کامل

بررسی مدت زمان لازم جهت شستشوی دست قبل از عمل جراحی

Infection may be caused by transfer of bacteria from the hands of the surgical team during operative procedures. Therefore carefull surgical scrubbing is performed to reduce the number of bacteria on the skin. The duration of scrubbing and the antiseptic solution are two variables in this purpose. One hundered sample were removed from the index pulp of Right hand of the surgeons. At t...

متن کامل

Fast Local Scrubbing for FPGAs

Memory scrubbing is used to mitigate SEU on susceptible devices. In the case of FPGAs, configuration memory scrubbing is generally used in conjunction with triple modular redundancy (TMR) to increase the reliability of FPGA systems in space borne applications. Reported solutions require a subsystem able to read and write from the configuration memory and retrieve from a “safe storage” a golden ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2000